Summary

Summary
Action
More Information
| Affected operating systems | Macintosh |
|---|---|
| Protection available since | 23 June 2008 05:41:04 (GMT) |
| Last updated | 23 June 2008 15:59:22 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
OSX/Hovdy-A is a Trojan for the Mac OS X platform.
When run the Trojan will attempt to install itself to the /Library/Caches folder and perform the following tasks:
- disable system logging and delete system log files
- start PHPShell and web server
- start ARD, VNC and SSH services
- disable system updates
- open ports in the firewall
- disable third party security software
- install LogKext keylogger
- steal various password hashes and keys which may be used to compromise other systems
OSX/Hovdy-A will also attempt to use the ARDAgent vulnerability to obtain root access.
